Connecticut AI Content Provenance Duty Took Effect October 1, 2026
Independently fact-checked against primary sources (last audited October 9, 2026). · 11 primary sources cited on this page. How we verify our legal content

Connecticut AI Content Provenance Duty Took Effect October 1, 2026
Connecticut's AI content provenance duty took effect October 1, 2026. Section 15 of Public Act No. 26-15 requires large consumer facing AI providers, to the extent commercially and technically reasonable, to include provenance data in AI created or materially altered audio, images and video. Only the Attorney General enforces it.
Information last verified on October 9, 2026. This is a developing story; we update it as the record changes.
Status: Section 15 is in force. Other sections took effect earlier, from passage and on July 1, 2026, and three later commencement dates run through January 1, 2028. The act's artificial intelligence working group owes the General Assembly a report by February 1, 2027.
Jurisdiction scope: This article covers Connecticut Public Act No. 26-15 (Substitute Senate Bill No. 5, 2026 regular session) and the Connecticut Unfair Trade Practices Act. It does not address federal AI rules or any other state's provenance, labeling or digital replica statute. For Connecticut's criminal synthetic media provisions, see our page on Connecticut deepfake laws and AI voice cloning penalties.
What Happened
On October 1, 2026, Section 15 of Connecticut Public Act No. 26-15 took effect. The measure began as Substitute Senate Bill No. 5 in the General Assembly's 2026 regular session and carries the formal title "AN ACT CONCERNING ONLINE SAFETY."
The Senate passed the bill as amended by Senate Amendment Schedule A on April 21, 2026. The House adopted the same amendment and passed the bill on May 1, 2026, and the measure went into concurrence that day. The Legislative Commissioners' Office designated it Public Act 26-15 on May 11, 2026.
The Governor approved it on May 27, 2026. That date appears both in the act's own Governor's Action line on page 74 of 74 and in the General Assembly's bill history for SB 5.
Section 15 carries its own commencement parenthetical in the enacted text: "Sec. 15. (NEW) (Effective October 1, 2026)". It occupies pages 27 through 29 and runs to three subsections: definitions in (a), the provenance duty and its exemptions in (b), and enforcement in (c).
The Governor's office announced the signing in a press release dated June 2, 2026, six days after the approval date. That release states that the Governor "today announced that he has signed into law" the legislation and gives no signing date of its own, so it does not conflict with the act. It describes chatbot safety protocols, employment disclosures and an AI regulatory sandbox, and it does not mention content provenance at all. The approval date of May 27, 2026 comes from the act's own Governor's Action line and from the chamber bill history.
What Section 15 Requires, in the Act's Own Words
The operative duty is subsection (b)(1):
"(b) (1) Except as provided in subdivision (2) of this subsection, each covered provider shall: (A) To the extent commercially and technically reasonable, include provenance data in any audio, image or video content, or in any content that is a combination thereof, that is created or materially altered by such covered provider's generative artificial intelligence system in a manner that allows a consumer to assess whether such content was created or materially altered by such covered provider's generative artificial intelligence system; and (B) Use commercially and technically reasonable methods, including, but not limited to, the relevant standard established by the Coalition for Content Provenance and Authenticity, to make the provenance data that are included in any content pursuant to subparagraph (A) of this subdivision difficult to tamper with, remove or disassociate from such content."
Public Act No. 26-15, Sec. 15(b)(1), at 27 to 28 of 74.
Four definitions in subsection (a) do most of the work, and each one narrows the duty.
"Covered provider" means "any person who creates, codes or otherwise produces a generative artificial intelligence system that (i) has more than one million users per month, and (ii) is publicly accessible to consumers for personal use," and it "does not include any federal, state or local government agency." Sec. 15(a)(2). The act does not say how a monthly user count is measured, nor whether the count is Connecticut specific or global.
"Generative artificial intelligence system" means "any technology that uses machine learning to generate images, audio or video," and includes "any system utilizing deep learning, natural language processing or other computational processing techniques of similar or greater complexity." Sec. 15(a)(3). Text generation is absent from that list, and the duty in (b)(1)(A) independently reaches only audio, image and video content, or combinations of them.
"Provenance data" means "data that are embedded into digital content or that are included in the digital content's metadata for the purpose of verifying the digital content's authenticity, origin or history of modification." Sec. 15(a)(6). Metadata satisfies the definition on its face; the act does not require a visible label.
"Materially alter" means "to substantially alter the data in any content," and it excludes "any minor modification that does not lead to a significant change in the perceived content or meaning thereof." The act then lists eleven examples of excluded edits: changes in brightness, contrast or color; sharpening; saturation; application of a filter; resizing; scaling; cropping; format conversion; resampling; denoising; and removal of background noise in audio. Sec. 15(a)(4).
The exemptions in subsection (b)(2)
Subparagraph (A) protects two categories of information. The duty does not require a covered provider to include "any information relating to an identified or reasonably identifiable individual" in provenance data. It also does not require disclosure of a trade secret, of information otherwise protected from disclosure under state or federal law, or of "any confidential or proprietary information concerning the design or use of a generative artificial intelligence system."
Subparagraph (B) carves out three use categories outright. The duty does not apply to "any business-to-business use, sale, licensing or distribution of a generative artificial intelligence system." It does not apply to any "product, service, Internet web site or application that solely provides consumers with video game or interactive experiences," and the act specifies that those experiences may include direct online sales of goods or services and letting consumers "virtually browse, select and purchase items." And it does not apply to "any system that is used solely for upscaling, noise reduction or compression."
Enforcement runs through CUTPA, and only through the Attorney General
Subsection (c) sets the remedy structure:
"(c) Any violation of the provisions of subsection (b) of this section shall constitute an unfair or deceptive trade practice for the purposes of subsection (a) of section 42-110b of the general statutes and shall be enforced solely by the Attorney General. The provisions of section 42-110g of the general statutes shall not apply to any such violation. Nothing in this section shall be construed as providing the basis for a private right of action."
Public Act No. 26-15, Sec. 15(c), at 29 of 74.
Section 15 contains no civil penalty figure of its own and no notice and cure period. Both appear elsewhere in the same act: Section 2 sets a civil penalty of up to one thousand dollars per violation for the frontier developer provisions, and Section 12 gives the Attorney General discretion to issue a curable notice of violation, with sixty days to cure, for automated employment decision violations occurring on or before December 31, 2027.
Two Things the Enacted Text Does Not Contain
Two descriptions attach to this act that its enacted text does not bear out. Both are set out below against Public Act No. 26-15 itself, which is the document an enforcement action or a court would read.
The enacted act is not titled the "CART Act"
A plain text search of all 74 pages of the enacted act returns no instance of "CART," no instance of "Connecticut AI Responsibility and Transparency Act," and no short title clause of the usual "this act may be cited as" form. The only title the enacted document carries is "AN ACT CONCERNING ONLINE SAFETY."
The nickname is not an invention of private commentary. The Governor's own announcement of the signing quotes State Representative Hubert Delany saying, "With the C.A.R.T. Act, Connecticut is choosing to lead with clear rules, public trust, and real accountability." So the label has semi official currency in Connecticut.
The narrow point is this: the name is a colloquial shorthand, it is not the enacted title, and it does not appear in the text that the Attorney General or a court would read. Citations should run to Public Act No. 26-15 or to Substitute Senate Bill No. 5 of the 2026 session. We verified only this act's text and make no claim about whether some other Connecticut bill ever carried that name.
The act contains no duty to "mark" content or make it "detectable"
A duty requiring developers of systems capable of generating synthetic digital content to ensure that such content is "marked" and "detectable" as synthetic is also attributed to this act. The enacted text imposes no such duty. The words "mark," "marked," "marking," "watermark," "detectable" and "detection" do not appear anywhere in the 74 pages of Public Act No. 26-15; the only "mark" forms in the act are "market," "marketed," "marketing" and "benchmarks." The only form of "detect" in the act is in Section 5, where an artificial intelligence companion must use evidence based methods to detect any user expression clearly indicating a risk of suicide, self harm or imminent physical violence.
What the act does contain on this subject is Section 18, effective July 1, 2026, which establishes a working group within the Legislative Department. Among ten assignments, subsection (b)(4) directs the group to "Propose legislation to (A) regulate the use of general-purpose artificial intelligence models, and (B) require social media platforms to provide a signal when such social media platforms are displaying synthetic digital content."
A direction to propose legislation is not a compliance obligation on any provider or platform. The act defines "synthetic digital content" in two places, Sec. 18(a)(3) and Sec. 24(a)(5), the latter in the rewrite of Conn. Gen. Stat. 32-7p that took effect July 1, 2026. Both definitions are identical: "any digital content, including, but not limited to, any audio, image, text or video, that is produced or manipulated by any form of artificial intelligence, including, but not limited to, generative artificial intelligence." That definition does reach text. Section 15, the provision that actually binds providers, does not use the term at all; its own definitions in Sec. 15(a) are the operative ones for the provenance duty.
Section 18 sets its own calendar. Initial appointments were due by July 31, 2026, the first meeting by August 31, 2026, and a report of findings and recommendations goes to the General Assembly's consumer protection committee by February 1, 2027, at which point the group terminates.
The "marked and detectable" formulation is genuine Connecticut legislative language, and the nearest source for it is this bill's own earlier draft. In Substitute Senate Bill No. 5 as reported out in File No. 338, Section 15 was a synthetic digital content section rather than a provenance section, occupying the same section number the provenance duty now occupies, and it would have required the developer of a system capable of generating synthetic digital content to "Ensure that the outputs of such artificial intelligence system or general-purpose artificial intelligence model are marked and detectable as synthetic digital content," with that duty running "on and after October 1, 2027." The word "provenance" appears nowhere in File No. 338. Senate Amendment Schedule A replaced that section. The Office of Legislative Research analysis of the amended bill records that Senate Amendment "A" "removes the underlying bill's provisions on synthetic digital content" and "adds provisions on embedded metadata," which is the provenance duty now in Section 15, and the analysis titles the enacted section "EMBEDDED METADATA." The General Assembly's bill status page for SB 5 still displays the pre-amendment statement of purpose, which says the bill would "require ... synthetic digital content to be detectable as synthetic digital content." A description of this act drawn from that statement of purpose, or from File No. 338, will not match the signed text.
Two earlier bills carried the same formulation and also never became law. Section 6 of the 2024 substitute for Senate Bill No. 2 (File No. 188) would have required a developer to "Ensure that the outputs of such artificial intelligence system are marked in a machine-readable format and detectable as synthetic digital content." The Senate passed that bill on April 24, 2024; it was tabled for the House calendar on April 25, 2024, and the bill history ends there. Section 7 of the 2025 substitute for Senate Bill No. 2 (File No. 603) carried a near identical duty, requiring outputs to be "marked and detectable as synthetic digital content" beginning October 1, 2026. The Senate passed that bill on May 14, 2025; it reached the House calendar on May 16, 2025, and its history likewise stops there. In both cases the quoted language is the file copy text.
October 1, 2027 appears three times in Public Act No. 26-15, all in Sections 8, 9 and 10, and in each place it fixes when the automated employment decision duties attach to technology deployed in the state. No marking or detection obligation attaches on that date or on any other date in the act. October 1, 2027 was, however, the date the struck File No. 338 version of Section 15 set for its marking duty, which is one reason that date and that duty are still described together.
What the Law Actually Says
Section 15 does not create a new enforcement regime. It plugs into the Connecticut Unfair Trade Practices Act, codified at Conn. Gen. Stat. chapter 735a. Section 42-110b(a) provides that "No person shall engage in unfair methods of competition and unfair or deceptive acts or practices in the conduct of any trade or commerce," and section 42-110b(b) directs the Commissioner of Consumer Protection and Connecticut courts to be guided by Federal Trade Commission and federal court interpretations of Section 5(a)(1) of the FTC Act.
Section 42-110g is CUTPA's private damages provision. It allows "Any person who suffers any ascertainable loss of money or property, real or personal, as a result of the use or employment of a method, act or practice prohibited by section 42-110b" to sue for actual damages, and it removes any requirement to prove public interest or public injury. Section 15(c) switches that provision off for provenance violations.
That drafting pattern recurs across the act, but not uniformly. Six sections tie a violation to CUTPA. Sections 1, 5, 6, 12 and 15 each provide that a violation "shall constitute an unfair or deceptive trade practice for the purposes of subsection (a) of section 42-110b of the general statutes and shall be enforced solely by the Attorney General." Section 39(g), which takes effect January 1, 2028, is the sixth: it provides that a violation of its subsections (b) to (e) "shall be deemed an unfair or deceptive trade practice under subsection (a) of section 42-110b of the general statutes," and it stops there, with no Attorney General exclusivity sentence, no 42-110g carve out and no private right of action sentence.
Within the five Attorney General only sections, four go further still. Sections 1, 5, 12 and 15 each state both that section 42-110g does not apply and that nothing in the section provides the basis for a private right of action. Section 6(c) is Attorney General only without either of those sentences. So the fuller pattern is a gradient rather than a single template: one CUTPA hook with no enforcement limits at all, one with Attorney General exclusivity alone, and four that also switch off CUTPA's private damages action.
The act also borrows from Connecticut's existing privacy statute rather than inventing new vocabulary. Section 7(7) defines "personal data" for the automated employment decision sections by reference to Conn. Gen. Stat. 42-515, the definitions section of chapter 743jj on data privacy and security, which is the Connecticut Data Privacy Act. Readers tracking how the state's privacy obligations fit together can start with our guide to consumer rights under the CTDPA.
Connecticut's provenance duty is also a different instrument from the digital replica and likeness statutes other states have adopted. Those statutes generally create rights against the unauthorized use of a person's voice or image; Section 15 imposes a disclosure style obligation on the producer of the system, with no reference to any individual's likeness. Sec. 15(b)(2)(A)(i) adds that the duty "shall not be construed to ... Require ... a covered provider to include any information relating to an identified or reasonably identifiable individual in the provenance data." That withholds a requirement; it does not prohibit a provider from including such information. Our coverage of California's digital replica legislation sets out that contrasting model, and our 50 state survey of deepfake and AI voice cloning laws tracks the criminal and civil side across jurisdictions.
What Else Took Effect October 1, 2026
Section 15 was not alone. Fifteen sections of the act carry an October 1, 2026 commencement date. The ones with operative duties are these.
Section 1 bars a subscription based provider of artificial intelligence technology from entering or renewing a consumer subscription, or collecting any fee for one, unless it has given the consumer written notice of the key terms and conditions and the consumer has given written notice accepting them. Enforcement is CUTPA, Attorney General only.
Section 2 protects whistleblowers at frontier AI developers. A frontier developer is defined by compute: a person doing business in the state who trains or intends to train a foundation model using more than ten to the twenty sixth power integer or floating point operations. No frontier developer may adopt any rule, policy or contract permitting retaliation against a covered employee who reasonably believes a reported issue shows activity posing a specific and substantial danger to public health or safety due to a catastrophic risk. Large frontier developers, meaning those with more than five hundred million dollars in annual gross revenues, must stand up an anonymous internal reporting channel by January 1, 2027. Civil penalties run to one thousand dollars per violation, recoverable by the Attorney General in the superior court for the judicial district of Hartford.
Sections 7 through 12 create the automated employment related decision technology framework, but with a one year runway: the developer duty in Section 8 and the deployer duties in Sections 9 and 10 apply to technology deployed in the state on or after October 1, 2027. Section 9 requires plain language disclosure that an employee or applicant is interacting with such technology, unless a reasonable person would deem that obvious. Section 10 requires a written pre decision notice naming the technology's trade name and purpose, the categories and sources of personal data it processes, how that data will be assessed, and the deployer's contact information. Section 11 preserves trade secret withholding but requires notice that information is being withheld and the basis for it.
Sections 13 and 14 amend the state's employment discrimination statutes, Conn. Gen. Stat. 46a-60(b) and 46a-81c. Both now provide that the use of an automated employment related decision technology "shall not be a defense against a complaint" alleging a discriminatory practice, and both allow the commission or a court to consider evidence of anti bias testing or similar proactive efforts, including the quality, efficacy, recency and scope of that testing and the response to its results.
Section 26 requires each employer serving a federal WARN Act notice on the Labor Department under 29 U.S.C. 2102(a) to disclose whether the layoffs relate to the employer's use of artificial intelligence or another technological change.
Section 38 bars a state agency from using artificial intelligence technology in delivering public assistance benefits, or in any function with a material impact on individuals' rights, civil liberties, safety or welfare, unless the use complies with policies and standards set by the Office of Policy and Management and the Department of Administrative Services. Where an agency is authorized to procure such technology, it must complete an AI impact assessment, submit it to the Commissioner of Administrative Services, and post it on the agency website at least sixty days before deployment.
Sections 30 and 37 round out the October 1, 2026 group with, respectively, a Treasurer's office outreach duty tied to the Connecticut AI Academy and an amendment to Conn. Gen. Stat. 4a-2e on state procurement.
The full commencement map
Every date below is taken from the enacted act's own "(Effective ...)" parenthetical for that section.
| Effective date | Sections | Subject matter |
|---|---|---|
| From passage (May 27, 2026) | 16, 28, 29, 32, 35 | Connecticut Academy of Science and Engineering legislative liaison fellows, economic development and AI workforce study provisions, an Attorney General technology fellowship pilot program |
| July 1, 2026 | 17, 18, 23, 24, 25, 27, 31, 34 | Connecticut AI Academy, the AI working group, education and workforce provisions |
| October 1, 2026 | 1, 2, 7, 8, 9, 10, 11, 12, 13, 14, 15, 26, 30, 37, 38 | AI subscription disclosures, frontier developer whistleblower rules, employment technology framework, discrimination statute amendments, content provenance (Sec. 15), WARN AI disclosure, state agency AI limits |
| January 1, 2027 | 4, 5, 6, 19, 20, 21, 22 | AI companion operator duties and minor user protections, agency notice duties |
| July 1, 2027 | 3, 33, 36 | AI regulatory sandbox plan, a Department of Consumer Protection independent verification pilot program for AI models, open data and Chief Data Officer provisions |
| January 1, 2028 | 39 | Covered operator duties on algorithmic feeds and minors' accounts on covered platforms |
Analysis: Why This Matters
The following is analysis from the Recording Law Editorial Team.
The most consequential thing about Section 15 may be how little it demands. The duty is qualified twice over, by "to the extent commercially and technically reasonable" in subparagraph (A) and again by "commercially and technically reasonable methods" in subparagraph (B). A provider that argues a given pipeline cannot carry durable provenance data is arguing inside the text of the statute, not against it.
The definitional limits narrow it further. Because "generative artificial intelligence system" is defined in Sec. 15(a)(3) as technology that uses machine learning to generate images, audio or video, and because the duty in Sec. 15(b)(1)(A) reaches only audio, image and video content, text output is outside the provision. The business to business carve out in Sec. 15(b)(2)(B)(i) also means a model licensed to another company, rather than offered to consumers for personal use, is not reached.
The enforcement design is narrow on the face of the text. Four of the act's six CUTPA linked sections, Sections 1, 5, 12 and 15, expressly disable Conn. Gen. Stat. 42-110g and state that no private right of action arises. For those four duties, including the provenance duty, the private damages action that CUTPA ordinarily supplies under section 42-110g is unavailable, and Sec. 15(c) assigns enforcement solely to the Attorney General.
Sec. 15(b)(1)(B) names "the relevant standard established by the Coalition for Content Provenance and Authenticity," but it does so inside an "including, but not limited to" clause, as one example of a commercially and technically reasonable method rather than as the required one. The provision therefore does not tie compliance to a single technical approach, and it does not identify what other methods satisfy subparagraph (B). The act also does not name a version or a document for that standard.
Finally, the "marked and detectable" formulation is genuine Connecticut legislative drafting, and the likeliest reason it is attached to this act is that it was in this act's own file copy. Section 15 of File No. 338 carried the marking duty until Senate Amendment Schedule A struck it and inserted the provenance duty in its place, and the bill status page's statement of purpose still describes the bill as requiring synthetic digital content to be detectable. The same formulation also sits in Sec. 6 of the 2024 substitute for Senate Bill No. 2 (File No. 188) and Sec. 7 of the 2025 substitute for Senate Bill No. 2 (File No. 603), each of which passed the Senate and stopped on the House calendar. In Public Act No. 26-15 the subject survives only as the Sec. 18(b)(4)(B) assignment to propose legislation. A description of this act drawn from the file copy, the statement of purpose or either earlier bill will not match the signed text.
How This Affects You
Section 15 creates no privately enforceable right. Subsection (c) states that nothing in the section provides the basis for a private right of action and that Conn. Gen. Stat. 42-110g does not apply, and it assigns enforcement solely to the Attorney General. The section's own definition of "consumer," at Sec. 15(a)(1), is "an individual who is a resident of this state," so the assessment the provenance data must make possible is framed around Connecticut residents.
The statute also contemplates less visible disclosure than the word provenance may suggest. Provenance data may sit in a file's metadata rather than on the face of the content, under Sec. 15(a)(6), and the duty requires only that the data allow a consumer to assess whether that provider's generative AI system created or materially altered the content. Nothing in Section 15 requires a visible label or an on screen notice.
Which systems the section reaches is a question of its definitions rather than of the technology. Sec. 15(a)(2) reaches a person who creates, codes or otherwise produces a generative AI system that has more than one million users per month and is publicly accessible to consumers for personal use, and it excludes government agencies. Sec. 15(a)(3) limits "generative artificial intelligence system" to technology that uses machine learning to generate images, audio or video. Sec. 15(b)(2)(B) then removes business to business distribution, products that solely provide video game or interactive experiences, and systems used solely for upscaling, noise reduction or compression. Because of those limits, the absence of a provenance record on a piece of AI media establishes nothing by itself, and the act's other sections carry their own scope and their own effective dates.
What Happens Next
Several dated events are already fixed in the act. The Section 18 working group's report of findings and recommendations is due to the General Assembly's consumer protection committee by February 1, 2027, and the group terminates when it files or on February 1, 2027, whichever is later. Section 18(b)(4)(B) directs the group to propose legislation requiring social media platforms to signal synthetic digital content, so that report is the act's only dated step on that subject.
The AI companion provisions in Sections 4 through 6 take effect January 1, 2027, as does the Section 2 requirement that large frontier developers have an internal anonymous reporting process in place.
The automated employment decision duties in Sections 8 through 10 attach to technology deployed in the state on or after October 1, 2027, with Section 12's curable notice of violation available to the Attorney General for violations occurring on or before December 31, 2027.
Section 3's AI regulatory sandbox plan provision takes effect July 1, 2027. Section 39, the covered operator duties on algorithmic feeds and minors' accounts on covered platforms, takes effect January 1, 2028 and is not yet in force. We will update this page as the working group reports and as any enforcement activity under Section 15 becomes part of the public record.
This is general legal information, not legal advice. It covers Connecticut state law and reflects sources verified on October 9, 2026. Laws change and this story is developing; consult a lawyer licensed in your jurisdiction about your specific situation.
Related articles
- Connecticut AI laws and regulation in 2026
- Deepfake and AI voice cloning laws by state
- Connecticut deepfake laws: AI images, voice cloning and penalties
- Connecticut data privacy law and CTDPA consumer rights
- California's digital replica and likeness bill, SB 1111
- State and federal AI laws tracker
Last updated: 2026-10-09. This is a developing story; details verified as of 2026-10-09.
Frequently Asked Questions
What does Connecticut's AI provenance law require?
Section 15 of Public Act No. 26-15, effective October 1, 2026, requires a covered provider to include provenance data in any audio, image or video content created or materially altered by its generative AI system, to the extent commercially and technically reasonable, in a manner that allows a consumer to assess whether the content was created or materially altered by that system. It must also use commercially and technically reasonable methods to make that data difficult to tamper with, remove or disassociate from the content.
Which companies are covered providers under Section 15?
Section 15(a)(2) defines a covered provider as any person who creates, codes or otherwise produces a generative artificial intelligence system that has more than one million users per month and is publicly accessible to consumers for personal use. Federal, state and local government agencies are expressly excluded. The act does not specify how the monthly user count is measured.
Does Connecticut's provenance duty apply to AI generated text?
No. Section 15(a)(3) defines a generative artificial intelligence system as technology that uses machine learning to generate images, audio or video, and the duty in Section 15(b)(1)(A) reaches only audio, image or video content or combinations of them. Text only output is outside the provision.
Is Connecticut's 2026 AI law called the CART Act?
Not in the enacted text. The act's only title is 'AN ACT CONCERNING ONLINE SAFETY,' and the strings 'CART' and 'Connecticut AI Responsibility and Transparency Act' do not appear anywhere in its 74 pages, nor does any short title clause. The nickname does circulate, including in a legislator's quote in the Governor's own signing announcement, but citations should run to Public Act No. 26-15 or Substitute Senate Bill No. 5 of the 2026 session.
Does Public Act 26-15 require AI content to be watermarked or detectable?
No. The words 'mark,' 'marked,' 'watermark,' 'detectable' and 'detection' do not appear in the enacted act. Section 18(b)(4)(B), effective July 1, 2026, directs an AI working group to propose legislation that would require social media platforms to provide a signal when displaying synthetic digital content, which is a recommendation assignment rather than a duty on any provider. The 'marked and detectable' language was in Section 15 of this bill's own file copy, File No. 338, until Senate Amendment Schedule A struck it and inserted the provenance duty in its place, and the bill status page still shows the pre-amendment statement of purpose describing a detectability requirement. The same formulation also appears in Connecticut's 2024 and 2025 Senate Bill No. 2 efforts, neither of which became law.
Can a consumer sue an AI provider for violating Section 15?
No. Section 15(c) makes a violation an unfair or deceptive trade practice under Conn. Gen. Stat. 42-110b(a) but provides that it 'shall be enforced solely by the Attorney General,' that Conn. Gen. Stat. 42-110g does not apply, and that nothing in the section provides the basis for a private right of action.
What counts as materially altering content under Section 15?
Section 15(a)(4) defines 'materially alter' as substantially altering the data in any content, and excludes minor modifications that do not significantly change the perceived content or meaning. The act lists eleven excluded edits: brightness, contrast or color changes, sharpening, saturation, filters, resizing, scaling, cropping, format conversion, resampling, denoising, and removal of background noise in audio.
Are video games and business-to-business AI exempt?
Section 15(b)(2)(B) carves out business-to-business use, sale, licensing or distribution of a generative AI system; products, services, websites or applications that solely provide consumers with video game or interactive experiences, which may include direct online sales and virtual browsing and purchasing; and any system used solely for upscaling, noise reduction or compression.
When do the rest of Public Act 26-15's requirements take effect?
The act staggers commencement across six dates. Sections 16, 28, 29, 32 and 35 took effect from passage on May 27, 2026; Sections 17, 18, 23 to 25, 27, 31 and 34 on July 1, 2026; Sections 1, 2, 7 to 15, 26, 30, 37 and 38 on October 1, 2026; Sections 4 to 6 and 19 to 22 on January 1, 2027; Sections 3, 33 and 36 on July 1, 2027; and Section 39 on January 1, 2028. Separately, the employment technology duties in Sections 8 to 10 attach only to technology deployed on or after October 1, 2027.
Updates
Independently fact-checked against the cited primary sources
Sources and References
- Connecticut Public Act No. 26-15 (Substitute Senate Bill No. 5, 2026), AN ACT CONCERNING ONLINE SAFETY, Sec. 15 (Effective October 1, 2026) and Sec. 18 (Effective July 1, 2026), approved May 27, 2026, Connecticut General Assembly(cga.ct.gov).gov
- Bill Status, Substitute for S.B. No. 5, Session Year 2026 (bill history: Senate passed April 21, 2026; House passed May 1, 2026; signed by the Governor May 27, 2026), Connecticut General Assembly(cga.ct.gov).gov
- Conn. Gen. Stat. ch. 735a, Secs. 42-110b (unfair trade practices prohibited) and 42-110g (action for damages; class actions), Connecticut General Statutes(cga.ct.gov).gov
- Conn. Gen. Stat. ch. 743jj, Sec. 42-515 (definitions, Connecticut Data Privacy Act), Connecticut General Statutes(cga.ct.gov).gov
- Governor Lamont Signs Legislation Establishing Youth Online Safety Protections, Regulations Over Artificial Intelligence, press release dated June 2, 2026 (quoting Rep. Hubert Delany on the 'C.A.R.T. Act'), Office of the Governor of Connecticut(portal.ct.gov).gov
- Substitute Senate Bill No. 2, File No. 188 (2024), Sec. 6 (synthetic digital content marking duty, not enacted), Connecticut General Assembly(cga.ct.gov).gov
- Bill Status, Substitute for S.B. No. 2, Session Year 2024 (Senate passed April 24, 2024; tabled for the House calendar April 25, 2024), Connecticut General Assembly(cga.ct.gov).gov
- Substitute Senate Bill No. 2, File No. 603 (2025), Sec. 7 (marked and detectable synthetic digital content duty, not enacted), Connecticut General Assembly(cga.ct.gov).gov
- Bill Status, Substitute for S.B. No. 2, Session Year 2025 (Senate passed May 14, 2025; tabled for the House calendar May 16, 2025), Connecticut General Assembly(cga.ct.gov).gov
- Substitute Senate Bill No. 5, File No. 338 (2026), Sec. 15 (synthetic digital content "marked and detectable" duty, struck by Senate Amendment Schedule A), Connecticut General Assembly(cga.ct.gov).gov
- OLR Bill Analysis, sSB 5 (File 338, as amended by Senate "A"), AN ACT CONCERNING ONLINE SAFETY (Senate Amendment "A" removes the synthetic digital content provisions and adds the embedded metadata provisions), Office of Legislative Research, Connecticut General Assembly(cga.ct.gov).gov